MEDIUM
The HiView module has a vulnerability of not filtering third-party apps out when the HiView module traverses to invoke the system provider
Published Nov 9, 2022
5.3
MEDIUMCVSS 3.1
EPSS 0.34%
Description
The HiView module has a vulnerability of not filtering third-party apps out when the HiView module traverses to invoke the system provider. Successful exploitation of this vulnerability may cause third-party apps to start periodically.
Affected products
-
- Version 11.0.1StatusaffectedConstraints-
- Version 12.0.0StatusaffectedConstraints-
- Version 12.0.1StatusaffectedConstraints-
- Version
-
- Version 2.0StatusaffectedConstraints-
- Version 2.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://consumer.huawei.com/en/support/bulletin/2022/11/ Vendor Advisory
- https://device.harmonyos.com/en/docs/security/update/security-bulletins-phones-202211-0000001441016433 Vendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-47495 Advisory
| Link | Providers | Tags |
|---|---|---|
| https://consumer.huawei.com/en/support/bulletin/2022/11/ | Vendor Advisory | |
| https://device.harmonyos.com/en/docs/security/update/security-bulletins-phones-202211-0000001441016433 | Vendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-47495 | Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner huawei
Published Nov 9, 2022
Updated May 1, 2025
Reserved Nov 1, 2022
Link CVE-2022-44553
CISA Vulnrichment
Updated May 1, 2025
ENISA EUVD
EUVD-2022-47495 Assigner huawei
Published Nov 9, 2022
Updated May 1, 2025
Exploited since n/a
Link EUVD-2022-47495